GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,831
Maven
5,000+
npm
4,462
NuGet
775
pip
4,226
Pub
12
RubyGems
972
Rust
1,093
Swift
47
Unreviewed advisories
All unreviewed
5,000+
186 advisories
Filter by severity
React Router has CSRF issue in Action/Server Action Request Processing
Moderate
CVE-2026-22030
was published
for
@remix-run/server-runtime
(npm)
Jan 8, 2026
Same-origin policy bypass in the Request Handling component. This vulnerability affects Firefox <...
Moderate
Unreviewed
CVE-2025-14331
was published
Dec 9, 2025
Parcel has an Origin Validation Error vulnerability
Moderate
CVE-2025-56648
was published
for
@parcel/reporter-dev-server
(npm)
Sep 17, 2025
Origin validation error vulnerability in BeeDrive in Synology BeeDrive for desktop before 1.4.3...
Moderate
Unreviewed
CVE-2025-8074
was published
Dec 4, 2025
A same-origin policy violation allowing the theft of cross-origin URL entries when using the...
Moderate
Unreviewed
CVE-2018-18494
was published
May 14, 2022
Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin...
Moderate
Unreviewed
CVE-2025-37734
was published
Nov 12, 2025
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6),...
Moderate
Unreviewed
CVE-2022-30228
was published
Jun 15, 2022
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80...
Moderate
Unreviewed
CVE-2025-12905
was published
Nov 8, 2025
In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic...
Moderate
Unreviewed
CVE-2025-53399
was published
Aug 1, 2025
A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of...
Moderate
Unreviewed
CVE-2024-44187
was published
Sep 17, 2024
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2....
Moderate
Unreviewed
CVE-2024-54490
was published
Dec 12, 2024
The origin of an external protocol handler prompt could have been obscured using a data: URL...
Moderate
Unreviewed
CVE-2024-10460
was published
Oct 29, 2024
Error handling for script execution was incorrectly isolated from web content, which could have...
Moderate
Unreviewed
CVE-2025-5263
was published
May 27, 2025
Flask-CORS allows for inconsistent CORS matching
Moderate
CVE-2024-6844
was published
for
flask-cors
(pip)
Mar 20, 2025
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported...
Moderate
Unreviewed
CVE-2025-21497
was published
Jan 21, 2025
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS...
Moderate
Unreviewed
CVE-2015-4495
was published
May 14, 2022
Liferay Portal fails to verify messages from the cluster network is trusted
Moderate
CVE-2025-62250
was published
for
com.liferay:com.liferay.portal.cluster.multiple
(Maven)
Oct 21, 2025
IBM Engineering Requirements Management Doors Next 7.0.2, 7.0.3, and 7.1 could allow an...
Moderate
Unreviewed
CVE-2025-2140
was published
Oct 12, 2025
A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the...
Moderate
Unreviewed
CVE-2025-42706
was published
Oct 8, 2025
A flaw has been found in CodeCanyon/ui-lib Mentor LMS up to 1.1.1. Affected by this vulnerability...
Moderate
Unreviewed
CVE-2025-11304
was published
Oct 5, 2025
webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
Moderate
CVE-2025-30360
was published
for
webpack-dev-server
(npm)
Jun 4, 2025
A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point ...
Moderate
Unreviewed
CVE-2025-20364
was published
Sep 24, 2025
elysia-cors Origin Validation Error
Moderate
CVE-2025-50864
was published
for
@elysiajs/cors
(npm)
Aug 20, 2025
HCL BigFix SaaS Authentication Service is vulnerable to cache poisoning. The BigFix SaaS's HTTP...
Moderate
Unreviewed
CVE-2025-52621
was published
Aug 16, 2025
Keycloak phishing attack via email verification step in first login flow
Moderate
CVE-2025-7365
was published
for
org.keycloak:keycloak-services
(Maven)
Jul 30, 2025
ProTip!
Advisories are also available from the
GraphQL API